VDB
CVE-2017-4963
CVE-2017-4963
PUBLISHED
CVSS 8.100000381469727 HIGH
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vulnerable to session fixation when configured to authenticate against external SAML or OpenID Connect based identity providers.
EPSS 0.90% · 56.3th percentile
Risk Scores
CVSS 3.0
8.100000381469727
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.90%
56.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| pivotal_software | cloud_foundry_cf-release | 0 |
| n/a | Cloud Foundry Foundation | Cloud Foundry Foundation |
| pivotal_software | cloud_foundry_uaa-release | 0 |
| pivotal_software | cloud_foundry_uaa | 2.0.0, 3.0.0 |
Timeline
- Jun 13, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 8, 2023 EPSS Score